Junglewise Threat Intelligence

CVE-2026-60154: Oracle E-Business Suite unauthorized data access in Application Object Library

CVE-2026-60154 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Technologies: Oracle E-Business Suite Application Object Library, Oracle Application Object Library. Vendors: Oracle.

Executive brief

A vulnerability exists in the core component of Oracle E-Business Suite, a suite of business applications used for enterprise resource planning and supply chain management. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete certain business data. This could lead to unauthorized data manipulation or the exposure of sensitive internal information.

Technical details

This vulnerability affects the Core component of the Oracle Application Object Library within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an unauthorized data access and manipulation flaw that can be exploited via HTTP. An attacker requires low-level privileges (authenticated user) and network access to the application to succeed. Successful exploitation allows the attacker to perform unauthorized read, update, insert, or delete operations on a subset of data managed by the Application Object Library. The vulnerability has a CVSS 3.1 base score of 5.4, reflecting impacts on confidentiality and integrity but not availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle E-Business Suite (Application Object Library) 12.2.3 - 12.2.15

Timeline

  • 2026-07-21: advisory: Initial advisory published by Oracle and NVD.

References

Related threats